SIG Lite
Control LOG-03
Extractive Review Standard
How to answer 'How long are security logs retained?' on a SIG Lite
Reviewer Guidance & Pitfalls
State the retention duration (industry standard is at least 365 days / 1 year for audit logs, with 30–90 days readily searchable in SIEM). Mention that audit logs are write-once / append-only and protected against tampering.
Example Answer Passing Enterprise Audit
Compliant Response Template
Audit and security logs are centralized in write-protected cloud storage, retained for a minimum of 365 days, and indexed for active querying for 90 days (SOC 2, CC7.2).
Filling out a CAIQ or SIG Lite right now?
QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.
Zero spam. 100% confidential. No credit card required.